Tag: UNC6384

UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats
News

UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats

In an effort to further Beijing's geopolitical objectives, a group of attacks targeting embassies in Southeast Asia and other organizations worldwide have been traced to a China-nexus threat actor identified as UNC6384. According to Patrick Whitsell, a researcher at Google Threat Intelligence Group (GTIG), this multi-stage assault chain uses sophisticated social engineering techniques to avoid detection, such as genuine code signing certificates, an adversary-in-the-middle (AitM) attack, and indirect execution methods. A well-known Chinese hacker collective known as Mustang Panda—also known as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta, Red Lich, Stately Taurus, TEMP.Hex, and Twill Typhoon—is thought to have tactical and tooling similarities with UNC638...